***HACKER WARNING in security.log

ASupport

Verified User
Joined
Jan 26, 2021
Messages
19
Hi All,

Over the last two days we get the following at backup showing in the security log: (i have used %% to obscure names etc)

"***HACKER WARNING /home/admin/user_backups/%%date%%/%%username%%/backup/%%_%%.conf has a newline or linefeed in the param value:"

I can't actually find this .conf file anywhere, is this a dynamic generation at backup? I also can't see any evidence of hacking on the system. Can anyone point me in the direction of narrowing this down or where any additional logs will be to give me more information on this warning and why it is being generated?

In the log in log viewer, i see red bullet points in the log string and when i hover over them i get either \u1a or \u1b, i assume this is what it is finding as an issue.

Any help would be appreciated

Thanks
 
Yeah I would open a SR then. Not a lot I see out there.. Report back
 
I believe we have narrowed down the issue to the way DA reads the MySQL tables during backup, MySQL included the ability to use sha-2 hashing for passwords. The authentication string obviously contains some non-printing characters, such as newlines. How do we raise this as a bug, I assume @DirectAdmin Support read these?
 
Back
Top